JumbledPath

MITRE ATT&CK: S1206 View on attack.mitre.org

Aliases: JumbledPath

Malware type
spyware
Family
Malware family
Operating systems
network-devices
Profile updated
2026-07-07 13:19:34

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

JumbledPath is a custom-built utility written in GO that has been used by Salt Typhoon since at least 2024 for packet capture on remote Cisco devices. JumbledPath is compiled as an ELF binary using x86-64 architecture which makes it potentially useable across Linux operating systems and network devices from multiple vendors.

Detection coverage

  • 170 Sigma rules

Malware & tools used

  • Network Sniffing (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Multi-Stage Channels (attack-pattern)
  • Hide Infrastructure (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Clear Linux or Mac System Logs (attack-pattern)

Used by threat actors

Reports & references

  • Cisco Talos — Salt Typhoon Analysis (report)
  • MITRE ATT&CK — S1206 (report)

External references